BSI C5 explained: what it is and how to get certified
BSI C5 is Germany's cloud security attestation standard. Learn what it covers, who needs it, the step-by-step path to certification, and how to map it to ISO 27001 and SOC 2.
If you sell cloud services to German businesses, public authorities, or healthcare organisations, there's a good chance a prospect has already asked for your BSI C5 attestation. Even if they haven't yet, they will. The German Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik, or BSI) created the Cloud Computing Compliance Criteria Catalogue, C5 for short, to set a verifiable, audited baseline for cloud security. Getting it right takes planning, but the path is manageable once you understand what's required.
What is BSI C5?
BSI C5 is a criteria catalogue published by the German Federal Office for Information Security (BSI) that defines minimum security requirements for cloud services. First introduced in 2016, it was substantially updated in C5:2020, and the latest evolution, C5:2026, extends requirements to address supply chain risks, AI use, and emerging regulatory alignment across Europe.
Compliance is demonstrated through an independent attestation based on the ISAE 3000 assurance standard, not through a BSI-issued certificate. The BSI does not conduct or issue attestations itself. Instead, licensed public accountants (Wirtschaftsprüfer) or accredited audit firms assess the cloud service provider (CSP) and issue the formal report.
Two attestation types exist:
- Type 1 confirms that controls are suitably designed at a specific point in time.
- Type 2 confirms that controls are both suitably designed and operating effectively over an observation period, typically six to twelve months.
As of July 2025, a Type 2 attestation is now mandatory for cloud providers serving Germany's healthcare sector under the Digital Act (DigiG) and §393 SGB V. Many public sector customers and enterprise buyers outside healthcare now expect Type 2 as a baseline too.
Who needs BSI C5?
C5 was originally built for cloud providers supplying German federal agencies, and for those organisations it remains a procurement prerequisite. Its reach has expanded considerably since then. A December 2025 analysis by RÖDL confirmed that C5 is establishing itself as a cross-industry cloud security standard in Germany, with the healthcare mandate acting as a catalyst for wider adoption.
Practically speaking, you should pursue C5 if your cloud service:
- Processes data for German or DACH-region public sector clients
- Handles patient or health insurance data under the German Social Code (SGB V)
- Is offered to financial institutions or critical infrastructure operators in Germany
- Competes in any market where enterprise buyers use it as a vendor selection criterion
SaaS and tech companies expanding into the German or broader European market will increasingly encounter C5 as part of procurement due diligence, even when it's not yet a legal requirement.
The 17 control domains
BSI C5:2020 organises its criteria across 17 security domains. According to Kiteworks' January 2026 analysis, the current catalogue contains 121 mandatory controls. The domains cover:
The last two domains are unique to C5. The transparency requirement around government investigation requests (INV) and the explicit product safety and security domain (PSS) go beyond what ISO 27001 or SOC 2 typically address. You'll also need to document exactly where customer data is stored and processed, data residency transparency is a hard requirement, not an optional disclosure.
The step-by-step path to getting BSI C5
Step 1: Scoping and gap assessment
Define which cloud service or services are in scope. C5 is assessed per service, not for the whole organisation. Once scope is agreed, run a structured gap analysis against the 17 control domains to identify where you're already compliant (often drawing on existing ISO 27001 or SOC 2 controls) and where remediation is needed. This phase typically takes two to six months, depending on your starting point.
Step 2: Remediation and documentation
Address the gaps. For most organisations, this means a combination of technical controls (logging, encryption, access management) and policy work (documented procedures, supply chain risk registers, incident response plans). Pay particular attention to the supplier management domain (SSO) and the investigation requests domain (INV), which are frequently underestimated. Document everything in a system description that will form the backbone of your audit evidence.
Step 3: Engage an accredited auditor
The BSI does not maintain a public list of approved auditors, but C5 audits must be conducted by a licensed German public accountant (Wirtschaftsprüfer) or an accredited audit firm experienced with ISAE 3000 engagements. Engage your auditor early, ideally before or at the start of the observation period for Type 2, so they can help validate your system description and agree the testing approach in advance.
Step 4: Observation period (Type 2)
For a Type 2 attestation, the auditor observes controls operating over a defined period, usually six to twelve months. During this window, maintain thorough evidence: access review logs, change management records, incident reports, supplier assessments, and training completion records.
Step 5: Audit execution and report issuance
The fieldwork phase, where the auditor interviews staff, tests controls, and validates evidence, typically runs two to four weeks. After review, the auditor issues the formal ISAE 3000 attestation report, which you then make available to customers as part of their own risk management process. Plan for four to eight weeks between fieldwork completion and final report.
Typical timelines and costs
End to end, including preparation, the observation period, and report issuance, reports put the realistic timeline at nine to twelve months for organisations new to C5. Organisations that already hold ISO 27001 or SOC 2 certifications will typically sit toward the lower end because large parts of their control environments already satisfy C5 criteria.
On costs, budgeting is context-dependent: complexity, scope size, and whether you need remediation support all affect the final figure.
Evidence checklist: what auditors typically look for
While every audit scope differs, these are the evidence categories that consistently feature in C5 assessments:
- ISMS documentation: Security policy, risk assessment reports, and the system description
- Access control: Role-based access matrices, access review logs, joiner-mover-leaver records
- Asset register: Inventory of all in-scope assets, including cloud-hosted infrastructure
- Incident records: Incident response plan, post-incident reports, and evidence of response testing
- Supplier assessments: Third-party risk registers, SLAs with security obligations, and complementary sub-service organisation controls (CSOCs)
- Physical security: Data centre access logs, visitor records, and environmental monitoring reports (or equivalent cloud provider attestations)
- Cryptography: Key management procedures and encryption configuration records
- Training records: Security awareness training completion logs for all relevant staff
- Data residency disclosures: Documentation of where customer data is stored and processed, including any sub-processors
- Investigation request procedures: Documented process for responding to government authority requests
If you already manage these artefacts for ISO 27001 or SOC 2, a significant portion can be repurposed directly.
How BSI C5 maps to ISO 27001 and SOC 2
C5:2020 was explicitly built to draw on ISO 27001, ISO 27017, and the CSA Cloud Controls Matrix. The BSI publishes official cross-reference tables showing which C5 criteria correspond to controls in ISO 27001 and ISO 27002. As a result, organisations holding an ISO 27001 certification have a meaningful head start, the access control, risk management, incident response, and change management domains overlap substantially.
Similarly, SOC 2 and C5 share strong alignment in their core trust service categories. The BSI's own FAQ notes that a C5 audit can be combined with a SOC 2 engagement to reuse elements of the system description and audit evidence.
The key differences:
- Data residency: C5 requires documented disclosure of processing locations; SOC 2 doesn't mandate this.
- Government investigation requests: The INV domain is unique to C5, neither ISO 27001 nor SOC 2 has an equivalent.
- Supply chain scrutiny: C5's SSO domain imposes more prescriptive third-party oversight than either framework.
- Cloud-native scope: Unlike ISO 27001, which covers the whole organisation, C5 scopes specifically to the cloud service being assessed.
If you're already working through a compliance comparison across ISO 27001, SOC 2, ISAE 3000, and NIS2, C5 fits naturally into a unified compliance programme rather than requiring a parallel effort.
How Securance can help
Securance supports cloud service providers across Europe through every stage of the C5 journey: from initial gap assessment through remediation planning to audit coordination and report issuance. Trusted by over 800 professional firms and SMEs, Securance's Single Audit, Multiple Standards approach means that if you're pursuing C5 alongside ISO 27001, SOC 2, ISAE 3402, NIS2, or DORA, the work is coordinated rather than duplicated.
The team covers all three pillars you'll need: advisory to align your ISMS and control environment with C5 requirements, assurance for the independent audit engagement itself, and network penetration testing and vulnerability scanning to meet the technical security criteria. Monthly cyber scanning also keeps your controls evidence current throughout the Type 2 observation window.
Frequently asked questions
Is BSI C5 a certification or an attestation? It's an attestation, not a certification. The BSI does not issue certificates. A licensed auditor issues a report confirming that your controls meet the C5 criteria, based on the ISAE 3000 standard.
Does BSI C5 apply outside Germany? Legally, C5 is a German standard. In practice, it's increasingly referenced across the DACH region and by European enterprise buyers who serve German-regulated sectors. The European cloud security landscape is converging, and C5 is one of the more mature national frameworks, making it relevant for any cloud provider with European ambitions.
Can I combine a C5 audit with my ISO 27001 or SOC 2 work? Yes. The BSI explicitly acknowledges that audit evidence can be reused across C5 and SOC 2 engagements, and ISO 27001 controls map directly to a large portion of C5 criteria. A coordinated approach saves time and reduces total audit cost.
Which C5 version should I be working towards? Organisations starting today should work to C5:2020. C5:2026 is now published, and the new catalogue will be required for assessments starting from June 2027. Your auditor can advise on the transition.
What's the minimum observation period for a Type 2 report? According to the BSI's FAQ, the observation period is three to twelve months. Six months is the most common practical minimum, balancing audit evidence requirements with time to market.
Getting your BSI C5 attestation is an investment in access, to the German market, to regulated sectors, and to enterprise buyers who treat it as a baseline for vendor due diligence. The sooner you start the observation period, the sooner you can put a Type 2 report in front of your next major prospect. If you'd like to understand where your current controls sit against the C5 criteria, a SOC 2 readiness checklist is a useful parallel starting point, and the Securance team is available to walk through your specific situation in a free consultation.